Impact
The vulnerability is a Contributor Cross‑Site Scripting flaw in the WordPress Strong Testimonials plugin up to version 3.3.11. It allows an attacker to inject malicious script through an untrusted input field, potentially subverting the integrity of the site’s content and enabling further exploitation such as session hijacking or defacement. The weakness falls under input validation failure (CWE‑79).
Affected Systems
Affected systems are installations of the WP Chill Strong Testimonials plugin running any version up to and including 3.3.11. The vulnerability manifests when the plugin is enabled on a WordPress site and the contributor form or similar input gateway is exposed to the web. No specific WordPress core or theme version is mentioned.
Risk and Exploitability
The CVSS base score of 6.5 indicates a medium severity with potential for client‑side impact. Because the EPSS score is not available, the exploitation probability is unclear but the lack of limited scope mitigations may make the flaw attractive to opportunistic attackers. As of now the vulnerability is not listed in the CISA KEV catalog, however, the absence of a listing does not preclude active exploitation, and the plugin vendor has issued a fix in version 3.3.12. The likely attack vector is a web‑based submission of malformed input through the plugin’s contributor interface.
OpenCVE Enrichment